期刊文献+

关于针对DDoS中Flood攻击的防御系统的研究

A Study on Defense System of Flood Attacks in DDoS
下载PDF
导出
摘要 本文主要针对DDoS中的Flood攻击的攻击特点,提出一种防御系统的结构,能够满足对不同Flood攻击检测的简易性、有效性的要求,并且与网络的地理位置、拓扑结构规模无关。该系统主要划分为检测攻击和确定攻击目标两个阶段。检测攻击阶段根据时攻击特征有较好描述性的源地址、目标地址、TCP报文的标志以及ICMP报文的类型,检测攻击是否发生。当检测出攻击发生,启动确定攻击目标阶段,找山攻击目标的具体IP地址。最后综合这两阶段的结果,提取攻击特征,将满足这些特征的数据包过滤掉,达到防御的效果。 This paper presents a defense system(two stage approaches),which has simple and robust approach to defend Flood attacks by observing network traffic.This system firstly monitors SYN count,ratio between SYN and other TCP packets, SYN/ACK count,FIN count,and ratio between ICMP Port Unreach andlCMP packets.And it finds Flood attacks and victims more accurately in the second stage.This system employs MULTOPS structure for finding victims more quickly and accurately.
出处 《微型电脑应用》 2006年第9期1-3,24,共4页 Microcomputer Applications
关键词 DDo FLOOD攻击 SYNFLOOD UDPFlood ICMPFlood MULTOPS结构 Flood attacks SYN Flood UDP Flood ICMP Flood MI JI TOPS structure
  • 相关文献

参考文献7

  • 1David Moore,Geoffrey M. Voelker and Stefan Savage,Inferring internet Denial of Service Activity[A]. USENIXSecurity Symposium, 2001 [C].
  • 2Akira Kanaoka, Eij i Okamoto Multivaricate Statistical Analysis of Network Traffic for Intrustion Detection [A]. IEEE, 1529- 4188/03,2003[C]
  • 3Haining Wang ,Danlu Zhang and Kang G. Shin“Detecting SYN Flooding Attack [A]. IEEE, 0 - 7803 - 7476 - 2/02,2002[C].
  • 4Seung - won Shin, K - young Kim, Jong - S00 Jang, D -SAT..Detcting SYN flooding Attack by Two-stage sta-tistical approach[A]. IEEE ,o- 7695-2262- 9/05,2005[c].
  • 5B. E. Brodsky, Nonparametric Methods in Change. Point Problems'Kluwer Academic Publishers [A]. ISBN:0792321227,1993[C].
  • 6Haling Wang,Danlu Zhang and Kang(3. Shin, "Chang- Point Monitoring for the Detection of DoS Attacks [A]. IEEE,TDSC - 0001- 0104,2004[C].
  • 7Thomer M. Gil and Massimiliano Poletto MULTOPS: a data- structure for bandwidth attack detection [A].USENIX Security Symposium, 2001[C].

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部